Uploaded image for project: 'Security Subcommitee'
  1. Security Subcommitee
  2. SECCOM-76

Vulnerability scanning tool

XMLWordPrintable

      There is frustration with NexusIQ and a demand for a new tool. It necessary to have a look at new tools

      https://jira.onap.org/browse/TSC-32 

      19-02-13

      Ongoing exchanges with Zygmunt on potential tool alternative coming from IBM - feedback expected by 20th of February.

      19-02-27

      Following the discussion with Zygmunt, feedback could be expected in W10 - we target both static and dynamic scanning - as it involves 2 different teams on IBM side, we will try to proceed in parallel.

       2019/03/20:
      Meeting with Whitesoftware was done. To be synchronizied with LFN for their feedback on this solution evaluation.
      Feedback from Zygmunt received that IBM has no longer a vulnerability scanner.

      2019/08/06:
      Meeting with both Nexus-IQ and Whitesoftware to be organized to synch on products configuration that would allow us to benchmark and compare them. Some Jenkins jobs are failing -it is blocking to complete the analysis.

       

            zwarico Amy Zwarico
            auztizza auztizza
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: